
BetaNewsã«ãããšãã€ã³ã¹ããŒã«æ°ã500,000ãè¶ ããäžäœ30ã®ã¢ããªã±ãŒã·ã§ã³ã®ãã¡ã94ïŒ ã«å°ãªããšã3ã€ã®äžãªã¹ã¯ã®è匱æ§ãå«ãŸãã77ïŒ ã«å°ãªããšã2ã€ã®é«ãªã¹ã¯ã®è匱æ§ãå«ãŸããŠããŸãã 30ã®ã¢ããªã±ãŒã·ã§ã³ã®ãã¡ã17ïŒ ãMITMæ»æã«å¯ŸããŠè匱ã§ããããã¹ãŠã®ããŒã¿ãæ»æè ã«ããååã«ããããŠããŸãã
ããã«ãã¢ããªã±ãŒã·ã§ã³ã®44ïŒ ã«ã¯ãã¹ã¯ãŒããAPIããŒãªã©ã®åŒ·åãªæå·åèŠä»¶ãæã€æ©å¯ããŒã¿ãå«ãŸããŠããã66ïŒ ã«ã¯ãŠãŒã¶ãŒã®ãã©ã€ãã·ãŒã䟵害ããå¯èœæ§ã®ããæ©èœã䜿çšãããŠããŸãã
ãã®ãããã¢ãã€ã«ããã€ã¹ã¯å€ãã®ã»ãã¥ãªãã£ã®è°è«ã®å¯Ÿè±¡ãšãªã£ãŠããŸãã ããããã¹ãŠãèæ ®ããŠã Hackenã§ã¯ãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãåæããããã»ã¹ã瀺ãããã«ãOWASP Mobile TOP10æ¹æ³è«ãæ€èšããããšã«ããŸããã
OWASP Mobile TOP 10ã¯ãã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ããã¹ãããããã®äž»èŠãªæ¹æ³è«ã®1ã€ã§ãã è¡š1ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã¬ãã«ãç¹åŸŽä»ããããã«äœ¿çšããã10ã®è匱æ§ã説æããŠããŸãã [2,7,11]
è¡š1ïŒè匱æ§ãšãã®èª¬æ
ãã | èåŒ±æ§ | 説æ |
M1 | ã¢ãŒããã¯ãã£äžã®å¶çŽã®ãã€ãã¹ïŒäžé©åãªãã©ãããã©ãŒã ã®äœ¿çšïŒ
| ãã®è匱æ§ã¯ããã©ãããã©ãŒã æ©èœã®äžæ£äœ¿çšãå¶éã®åé¿ããŸãã¯ãã©ãããã©ãŒã ã»ãã¥ãªãã£ç®¡çå¶åŸ¡ã·ã¹ãã ã®äžäœ¿çšã察象ãšããŠããŸãã Androidãã©ãããã©ãŒã ãiOSïŒTouch IDãšããŒãã§ãŒã³ã®å¶éãåé¿ããïŒãããã³ä»ã®ã¢ãã€ã«OSã®äž¡æ¹ã«å žåçã§ãã ã¢ãã€ã«ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®äžéšã§ããã»ãã¥ãªãã£å¶åŸ¡ã«åœ±é¿ããŸãã |
M2 | å®å šã§ãªãããŒã¿ã¹ãã¬ãŒãž | ãã®è匱æ§ã¯ãM2 + M4 Mobile Top Ten 2014ã®çµã¿åããã§ããããã«ã¯ãå®å šã§ãªãã¹ãã¬ãŒãžãšæå³ããªãããŒã¿æŒæŽ©ãå«ãŸããŸãã |
M3
| å®å
šã§ãªãéä¿¡
| éä¿¡ãœãŒã¹ã®ä¿¡é Œæ§ã®äžååãªç¢ºèªã誀ã£ãSSLããŒãžã§ã³ãäžååãªèª¿æŽæ€èšŒãã¯ãªã¢ããŒã¿ïŒã¯ãªã¢ããã¹ãïŒã§ã®æ©å¯ããŒã¿ã®éä¿¡ãªã©ã
|
M4 | å®å
šã§ãªãèªèšŒ
| ãã®è匱æ§ã¯ããšã³ããŠãŒã¶ãŒèªèšŒãŸãã¯ã»ãã·ã§ã³ã®èª€ç®¡çãæããŸãã 次ã®ã¢ã€ãã ãå«ãŸããŸãã
|
M5 | 匱ãæå·åïŒäžååãªæå·åïŒ | æå·åã¢ã«ãŽãªãºã ã䜿çšããŠæ©å¯æ
å ±ãéä¿¡ããŸãã æå·åã¢ã«ãŽãªãºã ã®äœ¿çšã¯ãç¹å¥ãªå Žåã«ã¯äžååãªå ŽåããããŸãã ãã®ã«ããŽãªã§ã¯ãæå·èŠçŽ ã®äžé©åãªäœ¿çšãæå·åŒ·åºŠã®åŒ±ããŸãã¯äžååãã®ãªãã·ã§ã³ã«ã€ããŠèª¬æããŸãã
TLSãŸãã¯SSLã«é¢é£ãããã®ã¯ãã¹ãŠM3ã«ããŽãªã«å±ããŸãã å¿ èŠã«å¿ããŠã¢ããªã±ãŒã·ã§ã³ãæå·åããŒã«ã䜿çšããªãå Žåãããã¯ã«ããŽãªãŒM2ã«åé¡ãããŸãã |
M6 | å®å šã§ãªãèªèšŒ | ãã®è匱æ§ã¯ãèªå¯ã®çæïŒã¯ã©ã€ã¢ã³ãåŽã§ã®æ€èšŒïŒæ€èšŒïŒã匷å¶è¡šç€ºãªã©ïŒã«ã€ããŠèª¬æããŠããŸãã ãã®ãããªã€ãã³ãã¯ãèªèšŒã®åé¡ïŒç»é²ããã€ã¹ããŠãŒã¶ãŒèªèšŒãªã©ïŒãšã¯ç°ãªããŸãã
å¿ èŠã«å¿ããŠã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒãèªèšŒããªãå ŽåïŒããšãã°ãèªèšŒããªãå Žåã«äžéšã®ãªãœãŒã¹ãŸãã¯ãµãŒãã¹ãžã®å¿åã¢ã¯ã»ã¹ãæäŸããäžæ£ã¢ã¯ã»ã¹ãçŠæ¢ããå ŽåïŒãããã¯èªèšŒãšã©ãŒã§ãããèªèšŒãšã©ãŒã§ã¯ãããŸããã |
M7 | ã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ãã³ãã®ç£èŠïŒã¯ã©ã€ã¢ã³ãã³ãŒãåè³ªïŒ | ãã®ã«ããŽãªã§ã¯ãå
¥åå¶åŸ¡ãèæ
®ãããŸãã ãµãŒããŒåŽã¢ããªã±ãŒã·ã§ã³ã§ã®ã³ãŒãããã³å®è£
ã®èšè¿°ãšã¯ç°ãªããã¯ã©ã€ã¢ã³ãåŽã¢ããªã±ãŒã·ã§ã³ã§ã®ã³ãŒãæè¡ã®å®è£
ã®åé¡ã ããã«ã¯ããããã¡ãªãŒããŒãããŒããã©ãŒãããæååã®è匱æ§ãããã³ã³ãŒãã¬ãã«ã§ã®ãã®ä»ã®ãšã©ãŒãå«ãŸããŸãããœãªã¥ãŒã·ã§ã³ã¯ãã¢ãã€ã«ããã€ã¹ã§å®è¡ãããã³ãŒããæžãæããããšã§ãã
|
M8 | ããŒã¿å€æŽïŒã³ãŒãæ¹ããïŒ | ãã®ã«ããŽãªã§ã¯ãå®è¡å¯èœãã¡ã€ã«ãããŒã«ã«ãªãœãŒã¹ã®å€æŽããµãŒãããŒãã£ããã»ã¹ããã®åŒã³åºãã®ã€ã³ã¿ãŒã»ãããã©ã³ã¿ã€ã ã¡ãœããã®çœ®æãã¡ã¢ãªã®åçãªå€æŽã«ã€ããŠèª¬æããŸãã
ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããåŸããã®ã³ãŒãã¯ããã€ã¹ã®ã¡ã¢ãªã«åžžé§ããŸãã ããã«ãããæªæã®ããã¢ããªã±ãŒã·ã§ã³ãã³ãŒããã¡ã¢ãªã®å 容ãå€æŽããã·ã¹ãã APIã¡ãœãããå€æŽãŸãã¯çœ®æããã¢ããªã±ãŒã·ã§ã³ã®ããŒã¿ãšãªãœãŒã¹ãå€æŽã§ããŸãã ããã«ãããæ»æè ã¯ãµãŒãããŒãã£ã®ã¢ããªã±ãŒã·ã§ã³ãæäœããŠãäžæ£ãªã¢ã¯ã·ã§ã³ãå®è¡ããããããŒã¿ãçãã ãããã®ä»ã®ééçå©çãåŸããããããšãã§ããŸãã |
M9 | ãœãŒã¹ã³ãŒãåæïŒãªããŒã¹ãšã³ãžãã¢ãªã³ã°ïŒ | ãã®è匱æ§ã«ã¯ããœãŒã¹ã³ãŒããã©ã€ãã©ãªãã¢ã«ãŽãªãºã ãªã©ã決å®ããããã®ãã€ããªãã¡ã€ã«ã®åæãå«ãŸããŸãã IDA ProãHopperãotoolããã®ä»ã®ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ããŒã«ãªã©ã®ãœãããŠã§ã¢ã¯ãã¢ããªã±ãŒã·ã§ã³ã®å
éšæäœã®ã¢ã€ãã¢ãæäŸããŸãã ããã¯ãã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã®æ€çŽ¢ãããã¯ãšã³ããµãŒããŒãæå·åããŒãç¥ç財ç£ãªã©ã®éèŠãªæ
å ±ã®æœåºã«äœ¿çšã§ããŸãã
|
M10 | é ãããæ©èœïŒå€éšæ©èœïŒ | å€ãã®å Žåãéçºè
ã«ã¯ãé ãããæ©èœãããã¯ãã¢ããŸãã¯æ©èœãã¢ããªã±ãŒã·ã§ã³ã³ãŒãã§ã®äžè¬çãªäœ¿çšãç®çãšãããã®ä»ã®ã¡ã«ããºã ãå«ãŸããŸãã ãããŸããã«ããã»ãã¥ãªãã£ã®ããç¥ãããŠããå®çŸ©ã¯ããã®ã«ããŽãªã«åé¡ãããŸãã éçºè
ã¯ããã€ããªããã¢ããªã±ãŒã·ã§ã³ã§èª€ã£ãŠãã¹ã¯ãŒããã³ã¡ã³ããšããŠæ®ãããšããããŸãã ãŸãã¯ããã¹ãäžã«äºèŠçŽ èªèšŒãç¡å¹ã«ããŠããå¯èœæ§ããããŸãã
|
OWASP Mobile TOP 10ã«åŸã£ãŠãã¢ããªã±ãŒã·ã§ã³ãPasswordManager-1.3-release.apkãããã¹ãããããã«ããªã³ã©ã€ã³ããã³ãã¡ã€ã«å ±æãªãœãŒã¹ã䜿çšãããè¡š2ã«èšèŒãããŠããããã°ã©ã ã»ããã®ã¿ã䜿çšããŸããã[6-10]
è¡š2ïŒäœ¿çšãããããã°ã©ã
ãã | åœ¹è· | 説æ |
1 | Apktool | APKãã¡ã€ã«ã解åããããã®ããã°ã©ã ã ãœãããŠã§ã¢ã®ããŒã«ã©ã€ãºãã¢ããªã±ãŒã·ã§ã³ã®æ§é ã®åæãªã©ã«äœ¿çšãããŸãã |
2 | adb | ããã¯Android SDKãšå
±ã«ã€ã³ã¹ããŒã«ãããããŒã«ã§ãOS Androidãå®è¡ããŠããããã€ã¹ã管çã§ããŸãã ã¯ã©ã€ã¢ã³ããµãŒããŒã®åçã§åäœããŸãã 5037ããŒãã䜿çšããŸãã
|
3 | dex2jar | ããã¯ãå€æŽãããAPKãã¡ã€ã«ãjarãã¡ã€ã«ã«å€æããããã«äœ¿çšãããããŒã«ã§ãã
|
4 | ããã¶ãŒ | ããã¯ãã¢ãã€ã«ããã€ã¹ãšããã°ã©ã ã®è匱æ§ãæ€çŽ¢ããããŒã«ãå«ããã¬ãŒã ã¯ãŒã¯ã§ãã ã¢ããªã±ãŒã·ã§ã³ãšããŠæ©èœããDalvikä»®æ³ãã·ã³ãä»ã®ã¢ããªã±ãŒã·ã§ã³ãããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšå¯Ÿè©±ããŸãã |
5 | VCGã¹ãã£ã㌠| ãœãŒã¹ã³ãŒãã®éçåæã®ããã®ããŒã«ã§ããã次ã®ããã°ã©ãã³ã°èšèªãåæã§ããŸãïŒC / C ++ãJavaãCïŒãVBãããã³PL / SQLã
|
6 | JD-GUI | ããã¯ãdex2jarã§äœ¿çšãããããŒã«ã§ãã ãªãŒãã³ãããéã³ã³ãã€ã«ããããœãŒã¹ã³ãŒããæäŸããŸãã
|
7 | ãžã§ãã¢ãŒã·ã§ã³ | Android OSãå®è¡ãããã¹ãä»®æ³ãã·ã³ãäœæããããã«èšèšããããœãããŠã§ã¢ã |
8 | Pidcat | ããã°ã©ã ãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã°ã衚瀺ããããã®ããã°ã©ã ã |
ãŸããApktoolããŒã«ã䜿çšããŠããã°ã©ã ãPasswordManager-1.3-release.apkããéã³ã³ãã€ã«ããŸãïŒå³1ãåç §ïŒã Apktoolããã°ã©ã ã«ããéã³ã³ãã€ã«ã§ã¯ããœãŒã¹ã³ãŒããç解ã§ãã圢åŒã§ååŸããããšã¯ã§ããŸããããã¢ãŒããã¯ãã£ãããã°ã©ã ã䜿çšããã©ã€ãã©ãªãªã©ã«ã€ããŠè©±ãåãä»ã®ããã°ã©ã ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã

å³ 1.éã³ã³ãã€ã«ãPasswordManager-1.3-release.apkãã

å³ 2.ãPasswordManager-1.3-release.apkãã®æ§é ã
å³ 2.ããã°ã©ã ã®apkãã¡ã€ã«ã®æ§é ãã€ãŸãïŒ
- AndroidManifest.xmlãã¡ã€ã«-èš±å¯ãã³ã³ããŒãã³ãã䜿çšãæšå¥šãããSDKããŒãžã§ã³ãããã³ãã®ä»ã®ã¢ããªã±ãŒã·ã§ã³èšå®ã«ã€ããŠèª¬æããŠããŸãã
- apktool.ymlãã¡ã€ã«-åã³ã³ãã€ã«ã®ããã«Apktoolãå¿ èŠãšãããµãŒãã¹æ å ±ãå«ãŸããŠããŸãã
- libãã£ã¬ã¯ããª-éçºè ããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã«è¿œå ã§ããŒãããã©ã€ãã©ãªãä¿åãããŸãã ãã®å Žåãæ¡åŒµåã.soã®ã©ã€ãã©ãªã䜿çšãããŸãã
- å ã®ãã£ã¬ã¯ããª-ãœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã®ãµãŒãã¹ãã¡ã€ã«ãä¿åãããŸãã
- ãã£ã¬ã¯ããªres-ãœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã®ãã¡ã€ã«ãã°ã©ãã£ãã¯ãããã³ãã®ä»ã®ãªãœãŒã¹ãå«ãŸããŠããŸãã
- smali-ãœãŒã¹ã³ãŒããã¡ã€ã«ã¯ãã€ãã³ãŒããšããŠä¿åãããŸãã
ããã°ã©ã ã®ãœãŒã¹ã³ãŒãã衚瀺ããã«ã¯ãdex2jarããŒã«ã䜿çšããŸãïŒå³3ãåç §ïŒã ããã«ãããããã°ã©ã ã®ãœãŒã¹ã³ãŒããVCG-scanneréçã³ãŒãã¢ãã©ã€ã¶ãŒã§æåã§åæããããšãå¯èœã«ãªããŸããïŒå³4ãåç §ïŒã

å³ 3. dex2jarã䜿çšããŠãœãŒã¹ã³ãŒããPasswordManager-1.3-release.apkããååŸãã

å³ 4. dex2jarã䜿çšããŠè¡šç€ºãããããã±ãŒãžãšã¯ã©ã¹ãPasswordManager-1.3-release.apkãã®æ§é
M1ã ã¢ãŒããã¯ãã£äžã®å¶çŽã®ãã€ãã¹ïŒäžé©åãªãã©ãããã©ãŒã ã®äœ¿çšïŒ

å³ 5. AndroidManifest.xmlãã¡ã€ã«
AndroidManifest.xmlãã¡ã€ã«ã«ã¢ã¯ã»ã¹ãããšãããã°ã©ã ã«é¢ãã次ã®æ å ±ãæäŸãããŸãã
- Androidã®æå°èš±å®¹ããŒãžã§ã³ã¯ãuses-sdk minSdkVersion = "23"ïŒAndroid 6.0ïŒã§ãã ãã®æ å ±ã«ãããããã°ã©ã ãåäœïŒãŸãã¯ãã¹ãïŒããããã€ã¹ïŒãŸãã¯ä»®æ³ãã·ã³ïŒã«å¿ èŠãªèŠä»¶ãããã«ç解ãããããããªãŒãã³ãœãŒã¹ã䜿çšããŠãã¿ãŒã²ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®è匱æ§ãèŠã€ããããšãã§ããŸãã
- ã¢ã¯ãã£ããã£ã®ãªã¹ãïŒWelcomeActivityïŒäžè¬ïŒãContentActivityãFormActivityã ãã®æ å ±ã¯ããŠãŒã¶ãŒãšããã°ã©ã ã®ããã¯ãšã³ãã®éã®å¯Ÿè©±ãæäŸãããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ããŒãã³ãã®ã¢ã€ãã¢ãæäŸããŸãã
- ãµãŒãã¹ïŒPasswordGeneratorServiceã ãã®ãµãŒãã¹ã®ååšã«ãããæå·åæ©èœã§åäœããã¯ã©ã¹ããã°ããèŠã€ããããšãã§ããŸãã
- ã³ã³ãã³ããããã€ããŒïŒUsersProviderïŒãšã¯ã¹ããŒã¿ãŒïŒã ã³ã³ãã³ããããã€ããŒã®ååšã«ãããå€éšãªãœãŒã¹ããã³ããŒã¿ããŒã¹ãšå¯Ÿè©±ããã¯ã©ã¹ãèŠã€ããããšãã§ããŸãã
M2ã å®å šã§ãªãããŒã¿ã¹ãã¬ãŒãž
ããã°ã©ã ã§ã¯ããããã°æ å ±ã®äžéšãã·ã¹ãã ãã°ã«è¡šç€ºã§ããŸãïŒå³6ããã³7ãåç §ïŒã ãã®å ŽåãREAD_LOGSæš©éïŒããšãã°ãlogcatãŸãã¯pidcatïŒãæã€ãµãŒãããŒãã£ã®ããã°ã©ã ã¯ãæ©å¯æ å ±ã«ã¢ã¯ã»ã¹ã§ãããããæ©å¯æ§ã䟵害ãããŸãã
ãã¹ãäžãpidcatããã°ã©ã ã䜿çšãããŸããïŒå³7ãåç §ïŒã ãã®è匱æ§ã¯ããã°ã©ã ã³ãŒãã§çºèŠãããŸããïŒå³8ãåç §ïŒ-éçºè ã¯ããœãŒã¹ã³ãŒãã®ãããã°ã«äœ¿çšãããLog.dïŒïŒé¢æ°ãæ®ããŸããã [6-8]
![]() | ![]() |
å³ 6.ãã¹ã¯ãŒãã¯æå·åãããŠããŸãã
| å³ 7.ããã°ã©ã ã®æäœäžãä¿åããããã¹ã¯ãŒãããã°ã«è¡šç€ºãããŸãã
|

å³ 8.ããŒã¿æŒæŽ©ã«ã€ãªããããã°ã©ã ã³ãŒãå ã®å Žæã
è匱æ§ãéããããã®æšå¥šäºé -ãã°å ã®ãããã°æ å ±ãåæ ãããœãŒã¹ã³ãŒãã®è¡ãåé€ãŸãã¯ã³ã¡ã³ãåããŸãã
Drozerãã¬ãŒã ã¯ãŒã¯ã§ããã°ã©ã ãåæãããšããšã¯ã¹ããŒããããã³ã³ããŒãã³ã-ContentProviderïŒå³9ãåç §ïŒãèŠã€ãããŸãããããã«ãããããã°ã©ã ã®URIã衚瀺ããããã°ã©ã ã䜿çšããããŒã«ã«ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸã[9]ã
app.provider.queryã¢ãžã¥ãŒã«ã䜿çšããŠããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã®ããŒã«ã«ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããŸãã

å³ 9.ãšã¯ã¹ããŒããããURI-ContentProviderããã³è匱æ§ã®å®è£ äŸã
ãœãŒã¹ã³ãŒããåæãããšãããŒã«ã«ããã°ã©ã ããŒã¿ããŒã¹ã§æ¿å ¥ãèŠã€ãããŸããïŒå³10ãåç §ïŒã èŠã€ãã£ãããŒã¿ã«ãããã·ã¹ãã ãžã®äžæ£ã¢ã¯ã»ã¹ãå¯èœã«ãªããŸãã

å³ 10.ããŒã¿ããªãŒãã³ã³ãŒãã§ãœãŒã¹ã³ãŒãã«ä¿åããŸãã
èŠã€ãã£ãè匱æ§ãä¿®æ£ããããã®æšå¥šäºé ïŒ
- ãã®ContentProviderã®AndroidManifest.xmlã®ãã¡ã€ã«ã¯ã次ã®ãã©ã°ãèšå®ããŸããandroidïŒexport = false and androidïŒprotectionLevel = "signature";
- ContentProviderã¯ããã©ã¡ãŒã¿ãŒåãããã¯ãšãªïŒqueryïŒïŒãupdateïŒïŒãdeleteïŒïŒïŒã䜿çšããŠã¢ã¯ã»ã¹ããå¿ èŠããããŸãã
M3ã å®å šã§ãªãéä¿¡
ããã°ã©ã ã§å®çŸ©ãããŠããAndroid OSã®æå°ããŒãžã§ã³ã§ã¯ããããã·ã䜿çšã§ããŸããã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã®æ©èœã䜿çšãããšã蚌ææžã眮ãæããããšã«ããããããã·ã®ãã©ãã£ãã¯åŸ©å·åã«å¯Ÿããä¿è·ãæäŸã§ããŸãã
ãã ããHTTPSãããã³ã«ãæå·åããµããŒãããŠããªãå Žåãããã°ã©ã ã¯HTTPSãããã³ã«ããHTTPãžã®èªååãæ¿ããå®è£
ããŸããããã«ããããªãŒãã³ãªäŒéãã£ãã«ã«ããæ
å ±ã®è»¢éãå¯èœã«ãªããŸãã
M4ã å®å šã§ãªãèªèšŒ
ãœãŒã¹ã³ãŒãã«ã¯ã次ã®é ç®ããã§ãã¯ãããªã¢ãŒããµãŒããŒã§èªèšŒãæäŸããæ©èœã¯ãããŸããã
- ãŠãŒã¶ãŒèå¥ã®æ€èšŒã«é¢ããèŠä»¶ã®æ¬ åŠ;
- å¶åŸ¡ã»ãã·ã§ã³ã®æ€èšŒã®æ¬ åŠ;
- ã»ãã·ã§ã³ç®¡çã®æ¬ ç¹ã
M5ã 匱ãæå·åïŒäžååãªæå·åïŒ
ã¢ããªã±ãŒã·ã§ã³ãœãŒã¹ã³ãŒãã®æååæã䜿çšããŠãFastCrypto.javaã¯ã©ã¹ãåæããŸãããããã¯ãMD5ã¢ã«ãŽãªãºã ã䜿çšããŠãã€ãé åãããã·ã¥ãµã ã«å€æããŸãïŒå³11ãåç §ïŒã MD5ã¢ã«ãŽãªãºã ã¯ããã¹ãäžã«ãã§ã«ä¿¡é Œæ§ãäœããšèŠãªãããŠããŸããã ãã®ããã·ã¥éã¯ããªã³ã©ã€ã³ãªãœãŒã¹ãšãœãããŠã§ã¢ããŒã«ã®äž¡æ¹ã䜿çšããŠéžæã§ããŸãã [13]
ããã°ã©ã ã®ããŒã«ã«ããŒã¿ããŒã¹ã®ãã¹ã¯ãŒãã¯ããå¡©ãªããã®ããã·ã¥å€ã«æ ŒçŽãããŸãïŒå³12ãåç §ïŒã Drozerã䜿çšããŠãããŒã¿ããŒã¹ãžã®ã¢ã¯ã»ã¹ãååŸããããã¹ã¯ãŒããèŠã€ãããŸããã ãã®åŸãMD5 Decrypterãªã³ã©ã€ã³ãµãŒãã¹ã䜿çšããŠããã¹ã¯ãŒããéžæãããŸããïŒå³13ãåç §ïŒã

å³ 11.ã©ã€ãã©ãªãæ¥ç¶ããããã·ã¥ã¢ã«ãŽãªãºã ãå®çŸ©ããŸãã

å³ 12.ããã·ã¥åãMD5ã¢ã«ãŽãªãºã ã«ãã£ãŠçæããããã¹ã¯ãŒãã

å³ 13.ããã·ã¥éã®éžæã®çµæã
ãœãŒã¹ã³ãŒãã¯VCGã¹ãã£ããŒããã°ã©ã ã«ãã£ãŠã¹ãã£ã³ãããããã°ã©ã ãããŒãããã¯ã®çæã«äœ¿çšãããè匱ãªã©ã€ãã©ãªïŒå³14ããã³15ãåç §ïŒã«æ¥ç¶ããŠããããšãããããŸããã å·çæç¹ã§ãjava.util.Randomã©ã€ãã©ãªã䜿çšããå Žåã次ã®ã©ã³ãã ãªå€ãèŠã€ããããšãã§ããŸããjava.security.SecureRandomã©ã€ãã©ãªã䜿çšããããšããå§ãããŸãã [12]

å³ 14. VCGã¹ãã£ããŒãã¹ãã£ã³ããåŸã«èŠã€ãã£ãè匱æ§ã

å³ 15.è匱ãªã©ã€ãã©ãªjava.util.Randomã
M6ã å®å šã§ãªãèªèšŒ
ããã°ã©ã ã«ã¯èªèšŒæ©èœããããŸããããããã°ã©ã ã®ç®æšã«åºã¥ããŠæäŸããå¿ èŠããããŸãã
M7ã ã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ãã³ãã®ç£èŠïŒã¯ã©ã€ã¢ã³ãã³ãŒãå質ïŒ
VCGã¹ãã£ããŒã䜿çšããŠã次ã®è匱æ§ãèŠã€ãããŸããïŒå³16ãåç
§ïŒã èµ€ã¯ããã¡ã€ã«åã®å
¥åãštry / catchãããã¯ã®äœ¿çšãå¶åŸ¡ããè匱æ§ã匷調ããŠããŸãã ããã«ãããããã°ã©ã ã®æäœãå®è¡å¯èœãã¡ã€ã«ã®ããŒãããã³èµ·åäžã«ãšã©ãŒãçºçããå¯èœæ§ããããŸãã Intentãªããžã§ã¯ãã®äœ¿çšã«é¢é£ããè匱æ§ã¯ç·è²ã§åŒ·èª¿è¡šç€ºãããŸãã OWASPã«ãããšããã§ãã¯ããã«å¥ã®ã³ã³ããŒãã³ãããIntentãªããžã§ã¯ããååŸããããšã¯è匱æ§ãšèŠãªãããŸãã
æšå¥šäºé
ïŒ
- try / catch以å€ã®ã³ã³ãããŒã«ãŠãããã®äœ¿çšã
- åä¿¡ãã©ã¡ãŒã¿ãšãã¡ã€ã«åãå¶åŸ¡ããŸãã
- åä¿¡æã«Intentãªããžã§ã¯ãã確èªããŸãã

å³ 16.ã¹ãã£ã³ã®çµæã
M8ã ããŒã¿å€æŽïŒã³ãŒãæ¹ããïŒ
Drozerãã¬ãŒã ã¯ãŒã¯ã䜿çšãããšãæœåšçãªSQLã€ã³ãžã§ã¯ã·ã§ã³ã®è匱æ§ãèŠã€ãããŸããïŒå³17ãåç §ïŒã ãã®è匱æ§ã«ãããããŒã«ã«ããŒã¿ããŒã¹ã«ä¿åãããŠããããŒã¿ãå€æŽããããšãã§ããŸãã æ€èšŒã®ããã«ãããŒã¿ããŒã¹å ã®ããŒã¿ãå€æŽããããšããŸãããïŒå³18ãåç §ïŒãæ å ±å€æŽèŠæ±ã«å¯Ÿããå¿çãåä¿¡ãããŸãã-ããŸã å®è£ ãããŠããŸãããïŒå³18ãåç §ïŒã ããã¯ãããŒã¿å€æŽã®èŠæ±ãããã°ã©ã ã«å®è£ ãããŠããªãããšãæå³ããŸãïŒå³19ãåç §ïŒããããã£ãŠãDrozerãã¬ãŒã ã¯ãŒã¯ã䜿çšããŠããã¹ãäžã«ããŒã¿ãå€æŽããããšã¯ã§ããŸããã [9]

å³ 17.ããŒã¿ããŒã¹ã®è匱æ§ã確èªããŸãã

å³ 18.èŠã€ãã£ãè匱æ§ã®æ€èšŒã

å³ 19.ããŒã¿å€æŽã®è匱æ§ã
M9ã ãœãŒã¹ã³ãŒãåæïŒãªããŒã¹ãšã³ãžãã¢ãªã³ã°ïŒ
ããã°ã©ã ã®ãœãŒã¹ã³ãŒãã¯é£èªåãããŠããªãããããœãŒã¹ã³ãŒããåæã§ããŸãã ããã°ã©ã ã³ãŒãã®åæã«ã¯ãapktoolããã³dex2jarããã°ã©ã ã䜿çšãããŸããã ãã®åŸãã¢ãŒããã¯ãã£ãšæ©èœãåæãããéçã³ãŒãã¹ãã£ã³ãå®è¡ããïŒå³1-5ã8ã10-11ã14-16ã18ãåç §ïŒãäžèšã®æœåšçãªè匱æ§ãæããã«ãªããŸããã
ãœãŒã¹ã³ãŒããä¿è·ããã«ã¯ãé£èªåããå¿ èŠããããŸãã æå·åã ãã§ãªããã³ãŒãåœé ãæ€åºããæ段ãè¿œå ããããšãå¿ èŠã§ãã
M10ã é ãããæ©èœïŒå€éšæ©èœïŒ
ãã¹ãäžã«é衚瀺ã®æ©èœãèŠã€ãããŸããã§ããã
çµè«
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ããã¹ãããããã«OWASP Mobile TOP 10ææ³ã䜿çšããå¯èœæ§ãåæããçµæãããã°ã©ã ãåä¿¡ãä¿åãåŠçããæ å ±ã®æ©å¯æ§ãæŽåæ§ãå¯çšæ§ã«éåããå¯èœæ§ã®ããæœåšçãªè匱æ§ã®æ°ãæ確ãã€ããžã¿ã«çã«åæã§ãããšçµè«ä»ããããšãã§ããŸãã ãããåæã«ãããã€ãã®æ¬ ç¹ãææãããŸãããã€ãŸããããã€ãã®è匱æ§ãç°ãªãã«ããŽãªã«åæã«å²ãåœãŠãããšãã§ãããããèŠã€ãã£ãè匱æ§ã®ãªã¹ã¯ãšãããéããæ¹æ³ãè©äŸ¡ããã®ãé£ãããªããŸãã ãããã£ãŠãOWASP Mobile TOP 10æ¹æ³è«ã®äœ¿çšã®æ確ãªãã¢ã³ã¹ãã¬ãŒã·ã§ã³ãè¡ãããããã°ã©ã ããªãªãŒã¹ããã¹ãã§ã¯ãªããšçµè«ä»ããããŸããã è匱æ§ã®æ°ãè¡š3ã«ç€ºããŸãã
è¡š3ïŒ
ãã | ã«ããŽãªãŒ | è匱æ§ã®æ° |
M1 | ã¢ãŒããã¯ãã£äžã®å¶çŽããã€ãã¹ãã | 1 |
M2 | å®å šã§ãªãããŒã¿ã¹ãã¬ãŒãž | 2 |
M3 | å®å šã§ãªãããŒã¿è»¢é | 1 |
M4 | å®å
šã§ãªãèªèšŒ
| 0 |
M5 | 匱ãæå·åŒ·åºŠ | 2 |
M6 | å®å šã§ãªãèªèšŒ | 0 |
M7 | ã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ã³ã³ãã³ãã®ç£èŠ | 2 |
M8 | ããŒã¿ä¿®æ£ | 1 |
M9 | ãœãŒã¹ã³ãŒãåæ | 1 |
M10 | é ãããæ©èœ | 0 |
- Sreenivasa Rao BasavalaãNarendra KumarãAlok Agarrwalã ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³-è匱æ§è©äŸ¡ã éçããã³åçåæãéããŠã -éä¿¡ããã³å¶åŸ¡ã·ã¹ãã ã®é²æ©ã«é¢ããäŒè°2013ã
- è匱æ§ãã¹ãïŒã¢ãã€ã«ã¢ããªã®ã»ãã¥ãªãã£ãã«ã¹ãã§ãã¯ã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //www.wired.com/insights/2013/04/vulnerability-testing-a-security-health-check-up-for-mobile-apps/-ã¹ã¯ãªãŒã³å
- ã¢ã¬ãã³ããã»ã¢ã«ã°ããã¬ããªãšã«ã»ããã¹ããã©ã³ã¯ãªã³ã»ãµã³ãã§ã¹ã Androidã¢ããªã±ãŒã·ã§ã³ã®ãã©ã€ãã·ãŒè匱æ§åæïŒå®çšçãªã¢ãããŒãïŒ2017ïŒã IEEE Xplore Digital Libraryã®é»åã©ã€ãã©ãªã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ http : //ieeexplore.ieee.org/document/7962545/
- ãªãããŒM.ãã¢ããŒã¯L.ãã¬ãªã£ã€ã¹ã ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã®è©äŸ¡-ããŒã1.èšç»ã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ http : //techgenix.com/assessing-security-mobile-applications-part1/-ã¹ã¯ãªãŒã³å
- ãªãããŒM.ãã¢ããŒã¯L.ãã¬ãªã£ã€ã¹ã ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã®è©äŸ¡-ããŒã2ãã¢ããªã±ãŒã·ã§ã³ã®ãã¹ãã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ http : //techgenix.com/assessing-security-mobile-applications-part2/-ç»é¢ã®åå
- ã¢ãã€ã«ã»ãã¥ãªãã£Wikiã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //mobilesecuritywiki.com-ç»é¢ã¿ã€ãã«
- DefconRUã ã¢ãã€ã«ã»ãã¥ãªãã£ã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //defcon.ru/category/mobile-security/-ã¹ã¯ãªãŒã³å
- æ å ±ã»ãã¥ãªãã£ã åºæ¬ããé«åºŠã Android [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //securitylabexpert.wordpress.com/android/-ç»é¢ã®ååã
- MWR Labsã ãããŒã¶ãŒã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //labs.mwrinfosecurity.com/tools/drozer/-ã¹ã¯ãªãŒã³å
- Appie-Android PentestingããŒã¿ãã«çµ±åç°å¢ã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //manifestsecurity.com/appie/-ã¹ã¯ãªãŒã³å
- OWASPã¢ãã€ã«ã»ãã¥ãªãã£ãããžã§ã¯ã[é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //www.owasp.org/index.php/OWASP_Mobile_Security_Project-ã¹ã¯ãªãŒã³å
- Javaä¹±æ°ãžã§ãã¬ãŒã¿ãŒã®ãããã³ã°ã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //xakep.ru/2015/07/20 / java-random-hack /-ç»é¢ããã®åå
- MD5ããããã³ã°ãããã¹ãŠã®æ¹æ³ã [é»åãªãœãŒã¹]-ã¢ã¯ã»ã¹ã¢ãŒãïŒ https : //xakep.ru/2013/10/13/md5-hack/-ç»é¢ããã®åå